Status:
Available
The Fortinet NSE 6 - FortiDLP 26 Administartor exam evaluates your knowledge of, and expertise with, FortiDLP design, deployment, configuration, policy enforcement, data protection, event investigation, and operational troubleshooting.
This exam tests your applied knowledge of FortiDLP configuration and operation. It includes operational scenarios, incident analysis, integration with third-party applications and directory systems, and shadow AI detection. It also includes troubleshooting scenarios related to endpoint agent deployment and communication, policies, and data-protection workflows.
Once you pass the exam, you will receive the following exam badge:

Audience
The Fortinet NSE 6 - FortiDLP 26 Administrator exam is intended for network and security professionals responsible for the design, deployment, configuration, monitoring, and troubleshooting of the FortiDLP solution. This solution aims to protect sensitive data on endpoints, on local or cloud storage services, and in SaaS applications.
Exam Details
| Time allowed |
60–70 minutes |
| Exam questions |
30–40 questions |
| Scoring |
Pass or fail. A score report is available from your Pearson VUE account. |
| Language |
English |
| Product version |
FortiDLP 26 |
Exam Topics
Successful candidates have applied knowledge and skills in the following areas and tasks:
FortiDLP fundamentals and deployment (25-35% of the exam)
| Tasks |
Details |
| Explain FortiDLP concepts and architecture |
- Data loss prevention (DLP) architecture
- FortiDLP solution
|
| Deploy FortiDLP tenants and agents |
- FortiDLP tenant
- Operator account types
- Operator access types
- Operator roles
- Manual deployment
- FortiDLP agent (Windows,macOS and Linux)
- Access tokens
- Bulk deployment
- Non-persistent virtual desktop infrastructure (VDI) deployment
- FortiDLP browser extensions
|
| Integrate FortiDLP with Software-as-a-Service (SaaS) |
- Directory synchronization
- Event Streaming Service API
- Webhooks for detection, incident, and audit log event subscription
- Microsoft 365 sensitivity label integration
- Microsoft SharePoint and OneDrive connectors
- Google Drive connector and labels
- Google Workspace user syncing
- Box account user syncing
- GenAI and SaaS application inventory with data risk analytics
- Real-time employee coaching through Slack and Teams messaging
- File sharing controls
- Corporate SaaS account logins
|
Data identification and enforcement (20-30% of exam)
| Tasks |
Details |
| Create and manage DLP policies |
- Policies
- Labels (custom, automatic, and directory)
- Custom policy templates
- Predefined policy groups
- Policy groups
- Microsoft SharePoint and OneDrive policies
- Google Drive policies
- Data identification and data profiles
|
| Configure actions and data protection |
- Preventive actions (file transfer, copy, printing, application usage)
- Action monitoring (log user activity with sensitive documents)
- Automated responses (quarantine files, encrypt sensitive files, trigger workflow integration)
- Policy application to channels (endpoint, network traffic, cloud apps)
|
| Manage assets, nodes, and user activity |
- Asset management
- Incident sequence rules
- Agent offline warning
- Agent configuration groups
- Manually node archiving
- Node management
- Organization node monitoring and maintenance
- FortiAnalyzer using FortiDLP connector integration
- FortiSIEM using FortiDLP connector integration
- Integration with Microsoft Entra ID, Google Workspace, and Box user integration
- LDAP Sync Tool
- User events
- User archiving
- User states and transitions
|
Detection and investigation (15-25% of exam)
| Tasks |
Details |
| Investigate events, cases, and incidents |
- User activity across endpoints and enterprise cloud drives
- Machine learning-powered behavior analytics
- MITRE ATT&CK® Insider Threat Detection Library
- Insider threat data exfiltration sequence
- Endpoint isolate and lock actions
- Forensics: clipboards, files, screenshots
- Secure Data Flow: DLP based on data origin
- Data lineage tracking with file manipulation detection
- Case management (assigning, viewing, and investigating cases)
- Events and incidents
- Policy violations
- Inline DLP for web, email, printers, clipboard, and removable media
- Real-time content inspection(on/off network)
|
| Monitor event visibility and behavior analytics |
- Insider threat data exfiltration sequence
- Endpoint isolate and lock actions
- Forensics: clipboards, files, screenshots
- Secure Data Flow: DLP based on data origin
- Data lineage tracking with file manipulation detection
- Risk scoring, anomaly detection
|
Troubleshooting (15-25% of exam)
| Tasks |
Details |
| Troubleshoot agent issues |
- FortiDLP agent deployment issues
- FortiDLP agent component issues
- FortiDLP agent performance issues
- FortiDLP agent connectivity issues
- FortiDLP decryption tool
- Evidence capturing
|
| Analyze audit logs, debug logs, and performance reports |
- Audit logs
- Agent performance reports
- Agent debug bundles
- FortiDLP agent crash reports
- Use cases: troubleshootng, forensics performance, crash reports
|
Training Resources
The following resources are recommended for attaining the knowledge and skills that are covered on the exam. The recommended training is available as a foundation for exam preparation. In addition to training, you are strongly encouraged to have hands-on experience with the exam topics and objectives.
Experience
- A minimum of 6 months of hands-on experience with FortiDLP
- Working knowledge of data classification and protection solutions